Oracle
oracle
11,112 CVEs • 1,067 products
Products (1,067)
Click to collapseToggle
Products (1,067)
Click to collapse
CVEs (11,112)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Opencv Oracle4Application Testing Suite Big Data Spatial And GraphEnterprise Manager Base Platform+1 moreJun 17, 2026 Jan 3, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV 4.1.0. A specially crafted XML file can cause a buffer overflow, resulting in multiple heap corruptions a...Show more |
4Debian FasterxmlNetapp+1 more30Active Iq Unified Manager Banking PlatformCommunications Billing And Revenue Management+27 moreJun 17, 2026 Jan 3, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking. |
3Knockoutjs OracleRedhat5Business Intelligence Decision ManagerGoldengate+2 moreJun 17, 2026 Jan 2, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without va...Show more |
4Canonical DebianOracle+1 more4Debian Linux Mysql WorkbenchSqlite+1 moreJun 17, 2026 Jan 2, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 selectExpander in select.c in SQLite 3.30.1 proceeds with WITH stack unwinding even after a parsing error. |
2Apache Oracle2Primavera Unifier SolrJun 17, 2026 Dec 30, 2019 N/A· v4 7.5 HIGH· v3 4.6 MEDIUM· v2 Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates in a configset `velocity/` directory or...Show more |
An information disclosure flaw was found in the way the Java Virtual Machine (JVM) implementation of Java SE 7 as provided by OpenJDK 7 incorrectly initialized integer arrays after memory allocation (in certain circumsta...Show more |
5Agendaless DebianFedoraproject+2 more5Communications Cloud Native Core Network Function Cloud Native Environment Debian LinuxFedora+2 moreJun 17, 2026 Dec 26, 2019 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 In Waitress through version 1.4.0, if a proxy server is used in front of waitress, an invalid request may be sent by an attacker that bypasses the front-end and is parsed differently by waitress leading to a potential fo...Show more |
8Debian NetappOpensuse+5 more11Backports Sle Cloud BackupDebian Linux+8 moreJun 17, 2026 Dec 24, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive. |
7Canonical DebianFedoraproject+4 more12Active Iq Unified Manager Clustered Data OntapClustered Data Ontap Antivirus Connector+9 moreJun 17, 2026 Dec 24, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc->oldNs. |
5Apache NetappOracle+2 more5Bookkeeper Cloud BackupMysql Workbench+2 moreJun 17, 2026 Dec 24, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 SQLite 3.30.1 mishandles certain parser-tree rewriting, related to expr.c, vdbeaux.c, and window.c. This is caused by incorrect sqlite3WindowRewrite() error handling. |
8Debian NetappOpensuse+5 more11Backports Sle Cloud BackupDebian Linux+8 moreJun 17, 2026 Dec 24, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a LEFT JOIN in which the right-hand side is a view. This can cause a NULL pointer dereference (or incorrect results). |
5Canonical DebianLinux+2 more168300 Firmware 8700 FirmwareA400 Firmware+13 moreJun 17, 2026 Dec 23, 2019 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 An exploitable denial-of-service vulnerability exists in the Linux kernel prior to mainline 5.3. An attacker could exploit this vulnerability by triggering AP to send IAPP location updates for stations before the require...Show more |
6Apache CanonicalDebian+3 more6Debian Linux LeapOncommand System Manager+3 moreJun 17, 2026 Dec 23, 2019 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manip...Show more |
5Apache CanonicalDebian+2 more11Agile Engineering Data Management Debian LinuxHyperion Infrastructure Technology+8 moreJun 17, 2026 Dec 23, 2019 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too...Show more |
8Debian NetappOpensuse+5 more11Backports Sle Cloud BackupDebian Linux+8 moreJun 17, 2026 Dec 23, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 multiSelect in select.c in SQLite 3.30.1 mishandles certain errors during parsing, as demonstrated by errors from sqlite3WindowRewrite() calls. NOTE: this vulnerability exists because of an incomplete fix for CVE-2019-19...Show more |
5Canonical DebianLinux+2 more14Active Iq Unified Manager Aff Baseboard Management ControllerCloud Backup+11 moreJun 17, 2026 Dec 22, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 kernel/sched/fair.c in the Linux kernel before 5.3.9, when cpu.cfs_quota_us is used (e.g., with Kubernetes), allows attackers to cause a denial of service against non-cpu-bound applications by generating a workload that...Show more |
5Agendaless DebianFedoraproject+2 more5Communications Cloud Native Core Network Function Cloud Native Environment Debian LinuxFedora+2 moreJun 17, 2026 Dec 20, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Waitress through version 1.3.1 would parse the Transfer-Encoding header and only look for a single string value, if that value was not chunked it would fall through and use the Content-Length header instead. According to...Show more |
5Agendaless DebianFedoraproject+2 more5Communications Cloud Native Core Network Function Cloud Native Environment Debian LinuxFedora+2 moreJun 17, 2026 Dec 20, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Waitress through version 1.3.1 implemented a "MAY" part of the RFC7230 which states: "Although the line terminator for the start-line and header fields is the sequence CRLF, a recipient MAY recognize a single LF as a lin...Show more |
6Apache CanonicalDebian+3 more17Application Testing Suite BookkeeperCommunications Network Integrity+14 moreJun 17, 2026 Dec 20, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening t...Show more |
5Apache DebianFedoraproject+2 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+7 moreNov 4, 2025 Dec 18, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been addressed in the maintained version of the library and has no current m...Show more |